Sophos XG VLAN

  Рет қаралды 30,753

Mike Faucher

Mike Faucher

Күн бұрын

Пікірлер: 60
@johnmitchell9538
@johnmitchell9538 2 жыл бұрын
Thank you so much for this video, I have been struggling with sophos ( we are just starting to use them at work ) this has made my day / week / month. Thank you so much.
@MikeFaucher
@MikeFaucher 2 жыл бұрын
Glad to hear that. Powerful but long learning curve. Best of luck.
@fat-Steve
@fat-Steve Жыл бұрын
Thaks for making this Mike. My understanding of what was going on just needed this video to tie it all together.
@MikeFaucher
@MikeFaucher Жыл бұрын
Glad to hear it helped.
@Shrav2112
@Shrav2112 5 жыл бұрын
I rarely comment but I had to say "thanks" for this vid. It stopped me banging my head against a wall and got my VLANs all sorted out now!
@MikeFaucher
@MikeFaucher 5 жыл бұрын
Glad it helped. Thanks for commenting.
@jeffmacdougall9190
@jeffmacdougall9190 2 жыл бұрын
This was very helpful. I have to take this to the next level. I have a Main Office with 2 branch locations connect to Main via Site-2-Site. Main Avaya VoIP system is in Main Office and I need to setup VLAN for all phones at all locations.
@MikeFaucher
@MikeFaucher 2 жыл бұрын
Glad i was help. For future reference, Sophos V19 has enhanced the site to site capability. Good luck and thanks for the feedback.
@MikeFaucher
@MikeFaucher 5 жыл бұрын
I know some of you have sent questions. I am out of the country for two weeks and will respond when I get back. Thank you.
@MAbdilahi
@MAbdilahi 6 жыл бұрын
thanks, i can't wait to see the next video wireless that connected to VLAN.
@MikeFaucher
@MikeFaucher 6 жыл бұрын
Thanks for the comment. WIll have something in the next week or two.
@GorkemYildirim
@GorkemYildirim 3 жыл бұрын
Great detailed information. Thanks a lot.
@MikeFaucher
@MikeFaucher 3 жыл бұрын
Glad it was helpful!
@GorkemYildirim
@GorkemYildirim 3 жыл бұрын
@@MikeFaucher your sophos xg videos thought me a lot indeed.
@danimoosakhan
@danimoosakhan 5 жыл бұрын
So after creating vlan on physical port, don't we have to trunk the port on the switch as well? I wonder how else the vlan is communicating across the switch. For example, if you have multiple vlans on single physical port on router, you would trunk the port on switch and create the vlans with the same vlan IDs on switch as well.
@MikeFaucher
@MikeFaucher 5 жыл бұрын
You are right and I actually did a separate video on the switch configuration. kzbin.info/www/bejne/jpTJZGCnbaZkl6c. Thanks for pointing this out.
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
Can you explain the need for the MASQ NAT rule? I don't quite understand what it does.
@MikeFaucher
@MikeFaucher Жыл бұрын
It is really just a SNAT and translates an external request to an internal device. It is used for things like port forwarding to route the external IP/Port to an internal IP.. Hope that helps.
@bimbsky2000
@bimbsky2000 2 жыл бұрын
you have assigned 2 vlans in port no.3 right? so what is the configuration in the switch? is that work with cisco trunk?
@MikeFaucher
@MikeFaucher 2 жыл бұрын
Have not used Cisco swithches but here is a different video. Things have changed a bit but this will better show how I configured it,
@r.mega.
@r.mega. 3 жыл бұрын
Thank you for video!
@MikeFaucher
@MikeFaucher 3 жыл бұрын
Glad you found it useful.
@ShairKhan-jx3rl
@ShairKhan-jx3rl Жыл бұрын
Awesome 👌
@MikeFaucher
@MikeFaucher Жыл бұрын
Thank you for the feedback!
@nanakwadjo2260
@nanakwadjo2260 6 жыл бұрын
Thanks for this video. Good job
@wallywoll7334
@wallywoll7334 6 жыл бұрын
Mike would you have any experience configuring VoIP phones within Sophos xg, preferred with a vlan. ALSO QOS Applied.
@SKfareed123
@SKfareed123 3 жыл бұрын
We have to create VLAN in switch also to communicate.
@MikeFaucher
@MikeFaucher 3 жыл бұрын
Good feedback, Thanks.
@amitsharma-rm3ir
@amitsharma-rm3ir 4 жыл бұрын
Hi Mike, Configuring IP addres for vlan is a feature of L3 Switch where we named it as SVI.....Then why do we need to configure it in firewall.....it's little confusing me.... however you taught very well....I understood everything what you said....but SVI in firewall why is it??
@MikeFaucher
@MikeFaucher 4 жыл бұрын
Good question. You actually only need in one or the other not both. Which you use depends on the equipment you have. Since I do not have a layer 3 switch, I used interfaces. Great point.
@amitsharma-rm3ir
@amitsharma-rm3ir 4 жыл бұрын
@@MikeFaucher so in this case...over the layer 2 switche we make same id of vlans???
@MikeFaucher
@MikeFaucher 4 жыл бұрын
@@amitsharma-rm3ir You can do it over VLAN interfaces in the router.
@mohamedboukredia4225
@mohamedboukredia4225 4 жыл бұрын
Hello @@MikeFaucher can you please give me more informations on how to connect sophos xg with cisco switch after creating Vlans..i mean , i have to use trunk port or acces ?and i thnk i have to create vlan also on cisco switch te performe communication.
@renjithknair7724
@renjithknair7724 5 жыл бұрын
sir how to create inter vlan routing between two vlan and how make trunk port to sent traffic to another switch?
@MikeFaucher
@MikeFaucher 5 жыл бұрын
RENJITH K NAIR By definition, the VLANs are isolated from each other. You can create a firewall rule that allows certain devices to talk with one another if you require that but under a normal VLAN configuration they only communicate with the WAN. If you allow full communication between two VLANS it mostly defeats the isolation.
@williamnichols7112
@williamnichols7112 4 жыл бұрын
Hi Mike, I really enjoyed your video, well done and easy to understand. I want to do this for a "security Camera" network, but would like to have people be able to access the NVR's on the VLAN from the LAN. Is that simply just adding a Firewall rule to allow the VLAN to see the LAN like you did for the WAN? Thanks again for a well done video.
@MikeFaucher
@MikeFaucher 4 жыл бұрын
You probably do want to add a specific rule that allows access only to the NVR, not the entire VLAN. Another word to "allow" the LAN to access the NVR IP address.
@williamnichols7112
@williamnichols7112 4 жыл бұрын
@@MikeFaucher Thank you sir. I look forward to learning more from you.
@samueladuamah-yeboah8179
@samueladuamah-yeboah8179 3 жыл бұрын
Hi mike this is Exact video i was looking for because i want two networks setup Residential and Office and i want these networks on different firewall rules. Also i want to setup one more Vlan for Nvr use without internet is that possible?
@MikeFaucher
@MikeFaucher 3 жыл бұрын
Absolutely. The process is exactly the same except select deny when creating a firewall rule for that NVR VLAN. Hope that helps.
@samueladuamah-yeboah8179
@samueladuamah-yeboah8179 3 жыл бұрын
@@MikeFaucher Thanks for this advice cheers
@christian4553
@christian4553 4 жыл бұрын
Hello Mike, this video was really helpful, it helped put me in the right direction on what i want to achieve as regards vlans and UniFi APs. having a little trouble though after all is done and client/hosts connects to the wireless network created with the vlan! DHCP wont lease IPs, they get a strange IP not mentioned in the whole config. any help on how to troubleshoot this will be appreciated.
@MikeFaucher
@MikeFaucher 4 жыл бұрын
I am not 100% sure what you are seeing in terms of IP address. The biggest issue I have seen with VLANs is making sure that are setup from start to finish. Specifically, starting from the AP, you need to define a separate WiFI network and it should be set to use the VLAN ID that you want to use. From there, your switch has to be a managed switch or VLAN aware and lastly, your router has to have the DHCP and interface that is dedicated to the that VLAN. It really sounds like there is no DHCP that has been setup. Unify AP are easy to setup with wireless networks but they rely on your router/gateway for DHCP. If you are using Sophos, make sure that you have a dedicated DHCP for the VLAN. Not sure if that helped but let me know.
@christian4553
@christian4553 4 жыл бұрын
@@MikeFaucher Thanks for you quick response, it is very appreciated. i did define a separate WiFi Network and set it to use the VLAN ID that i want it to use, also my switch is a manage switch and VLAN aware as i have a couple of those on there as well. i am using Sophos and UniFi AP Pros so it was a complete verbatim replication from you two videos. created the VLAN interface on my sophos under my LAN interface, created a DHCP and assigned it the VLAN interface with the IP lease range, created IP range under host and services, finish up with a firewall rule and then move over to UniFi Controller and created a new WiFi Network with VLAN ID created earlier. but when clients connect, they don't get assigned the IP range specified in my DHCP and so no internet. dont know whats going wrong
@MikeFaucher
@MikeFaucher 4 жыл бұрын
@@christian4553 Interesting sounds like you did everything right but something is off if you are not getting the IP range. I assume your devices do not connect to the internet? What range of IP did you expect and what are you getting? I am assuming your switch is set to pass through VLAN traffic? It truly sounds like your devices are not getting to the DHCP server and are being blocked by your switch. Hard to be exact without seeing your exact configuration.
@michaelroberts151
@michaelroberts151 6 жыл бұрын
Hi Mike, Thanks for the video. I was wondering why you defined IOT as a range (the whole range) and not just defined it as /24 network? Thanks, Mike
@MikeFaucher
@MikeFaucher 6 жыл бұрын
You can do either but I had more predictable behavior when I defined the range. Certainly interested if you get different results. Thanks for the comment.
@christiankimangeles9468
@christiankimangeles9468 5 жыл бұрын
Do you have a a video on how to connect Unifi AC Pro to Sophos XG?
@MikeFaucher
@MikeFaucher 5 жыл бұрын
Not directly but I can something to my list for future consideration. Is the what you are looking more on AC Pro or configuring a dedicated port for AP on Sophos? It will help me if you expand on your question. Thanks for the comment.
@christiankimangeles9468
@christiankimangeles9468 5 жыл бұрын
@@MikeFaucher we have an existing network, so if possible I would like to create a VLAN on my current LAN and use the VLAN on may AC Pro, btw i dont have USG
@MikeFaucher
@MikeFaucher 5 жыл бұрын
Thanks for the explanation. Have you seen this one yet: kzbin.info/www/bejne/jpTJZGCnbaZkl6c
@johnmax2503
@johnmax2503 5 жыл бұрын
Hi ,Can u be in port one to recieve the tag aswell ,or must u be plugged into poert 3 where its binned.
@MikeFaucher
@MikeFaucher 5 жыл бұрын
If I understand the question, you can attach the VLAN to any LAN port that you are using so if you have your internal LAN on Port 1, you can and should create VLAN to that port. You have to attach VLANs to the same port you LAN is on. I hope that helps and thanks for the question.
@renjiithknair8869
@renjiithknair8869 5 жыл бұрын
Also your 3rd port is reserved for second network. So how it is possible to create the vlan on same port number 3??
@MikeFaucher
@MikeFaucher 5 жыл бұрын
RENJIITH K NAIR Good question. VLANs have to be bound to any physical LAN port so you can create VLANs that are either or both LAN ports, Though it makes things a bit confusing, depending on the physical wiring, I can have a VLAN on one network and a different VLAN completely separate on a different port/network. For clarity, it is always easier to have on physical network and multiple VLANS on that same network. That would be more versatile.
@renjiithknair8869
@renjiithknair8869 5 жыл бұрын
@@MikeFaucher sir also one of the qnap training video .. am waiting for that...how to secure qnap nas..
@MikeFaucher
@MikeFaucher 5 жыл бұрын
@@renjiithknair8869 I will add it to my list. Thanks for the suggestion.
@JamesRossBowles
@JamesRossBowles 6 жыл бұрын
Love the video, but its possibly named wrong. This was very helpful and could possibly help a lot more people, as the Sophos video tutorials are sparse.
@MikeFaucher
@MikeFaucher 6 жыл бұрын
Thanks for the feedback and pointing out my naming issue. I appreciate you telling Did not catch that. Thanks again.
@sahilhussain3647
@sahilhussain3647 5 жыл бұрын
Hi sir, your video is very good.i just want know how we can make the communication between that vlan(iot) to Port 1 and Port 1 to vlan( iot)
How to structure networks with VLANs
18:36
Christian Lempa
Рет қаралды 124 М.
ВЛОГ ДИАНА В ТУРЦИИ
1:31:22
Lady Diana VLOG
Рет қаралды 1,2 МЛН
The Lost World: Living Room Edition
0:46
Daniel LaBelle
Рет қаралды 27 МЛН
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,4 МЛН
Guest Wi-Fi over Mesh with VLAN tunneling
17:13
OneMarcFifty
Рет қаралды 26 М.
Sophos XG Bridge Mode
39:23
Mike Faucher
Рет қаралды 18 М.
VLANs in OpenWrt 21
28:27
OneMarcFifty
Рет қаралды 193 М.
Sophos V18 - Firewall and NAT rules
29:20
Mike Faucher
Рет қаралды 16 М.
VLANs SAVED my home network
17:23
SpaceRex
Рет қаралды 78 М.
How to Configure VLAN in Sophos XG Firewall
27:24
CYBERSKY
Рет қаралды 20 М.
ВЛОГ ДИАНА В ТУРЦИИ
1:31:22
Lady Diana VLOG
Рет қаралды 1,2 МЛН